Every answer and its explanation appears here once you have finished the path. Each one then links to the matching glossary entry, where the concept is set out in full with its worked example.
1. In an attack on a healthcare operator, the attackers exfiltrate five hundred thousand medical records before encrypting the systems. What does that exfiltration change about the nature of the loss?
It shifts the risk from availability to confidentiality, and restoring systems does not undo it
Data exfiltration is the unauthorised transfer of information to an outside recipient controlled by the attacker, and it is the mechanism of double extortion: it is the threat of publication that creates pressure beyond encryption alone. The insurance consequence is a change of nature, not merely added severity. An availability failure can be repaired: backups are restored, operations resume, the business interruption is counted and it ends. A confidentiality failure cannot be repaired, because data that has left does not come back. The loss then opens a second series of heads that restoration does not close, notification to the supervisory authority, individual notice to the people concerned, monitoring, litigation, and these run for years. That is why a claim where everything was paid and restored can stay open long after the systems work again.
Glossary entry · exfiltration-donnees2. LockBit dominated the ransomware-as-a-service market for over four years, claiming more than two thousand victims, until its takedown in February 2024. What does that model say about the structure of the risk?
That the threat is industrialised and affiliate-based, therefore reproducible and transferable after a takedown
LockBit names both a criminal group and the ransomware strain of the same name, which appeared in late 2019 as ABCD, then became LockBit 2.0 in 2021 and LockBit 3.0, known as Black, in 2022, the latter incorporating code from the BlackMatter leak. Two features of this model matter for assessing the risk. The first is industrialisation: ransomware as a service separates whoever writes the code from whoever runs the attack, multiplying operators without multiplying the skills required, and making the activity insensitive to the loss of any individual. The second is reuse, visible in the adoption of BlackMatter's code: strains do not die, they recombine. This is why the February 2024 takedown, which reached targets in a hundred and eleven countries including hospitals, water infrastructure and public administrations, reduces the threat without ending it, the affiliates and the code remaining available elsewhere.
Glossary entry · lockbit3. A finance director wires 480,000 euros on an email appearing to come from the chief executive, in fact sent from a look-alike domain. No system was encrypted or breached. How does this loss qualify?
As funds transfer fraud, distinct from attacks on systems
Business email compromise, known in France as faux ordre de virement when it targets finance teams, means impersonating or compromising the email account of an executive, supplier or partner to have a transfer executed to an account the attacker controls. What sets it apart is decisive for characterisation: no system is necessarily breached or encrypted, the attack targets a procedure and a relationship of trust, not an infrastructure. It follows that the loss falls neither under business interruption, since operations continue, nor under covers tied to a compromise of systems, since there is none. It falls under funds transfer fraud cover, which almost always carries a sub-limit far below the policy's headline limit. An underwriter unaware of that boundary may believe an exposure covered to the full limit when it is covered only to a fraction, and the difference surfaces at claim time.
Glossary entry · bec-fraude-virement4. In a double extortion, decryption keys are obtained free of charge following action by the authorities. What is left to decide?
The fate of the publication leg: keys restore access to data, they neither erase what was exfiltrated nor the threat to disclose it
Double extortion rests on two independent levers, encryption and publication, and a key answers only the first. Treating the incident as closed because production has restarted leaves open the part that binds the insured longest, the exfiltrated data, with its notification duties and its liability exposure. It is a competent professional's error because the return of operations is the most visible and most awaited signal. Characterization under the aggregation clause is a real question, and it stays open for the cedant, but it does not replace this one: it decides how several files group together, not what remains to be handled inside each.
Glossary entry · double-extorsion5. In what way are silent cyber and an attribution divergence between two lines of a tower the same flaw in two forms?
Both are exposures nothing measures: one because the contract says nothing, the other because the table does not read what the contracts say
The comparison is not a rhetorical flourish, it names one family of risks: those appearing in no aggregate because the measuring instrument does not go looking for them. Silent cyber is invisible because the policy is silent; the attribution hole is invisible because the control tool adds instead of reading. In both cases the charge exists, it is neither priced nor reserved, and it surfaces at the claim. The answer separating them by line of business is the most instructive to dismiss: it is accurate as description and wrong as conclusion, and it is precisely that compartmentalization that prevents anyone from seeing that one industrial attack aggregates in two portfolios at once, with neither aggregation study looking at the other half.
Glossary entry · silent-cyber6. A mid-sized company renews its contracts after the 2019 Lloyd's directives. It takes out a stand-alone cyber policy, and on the same day its property and liability policies are amended to exclude cyber unambiguously. What does doing both at once achieve?
A cyber loss can no longer be claimed twice, nor fall between two contracts
Isolating cyber in a dedicated contract does not make silence disappear, it moves it to the seam between contracts. As long as the property policy stays silent, one loss can fall under both the stand-alone cover and the conventional cover, which opens two symmetrical and equally costly arguments: double recovery, where two insurers contribute to the same damage with no written allocation, and the coverage gap, where each points to the other. The two steps therefore hold together, and the order matters: it is the exclusion written into the traditional policies that gives the stand-alone policy a clean scope, and it is the stand-alone policy that makes that exclusion bearable for the insured. Program coordination then becomes work in its own right, because contracts do not all renew on the same date and a quarter's drift is enough to reopen the seam. The other answers raise real but separate matters: how a program is structured changes neither third parties' right of action, nor the insured's disclosure duties, nor the content of war clauses, which are negotiated contract by contract.
Glossary entry · police-stand-alone7. An 18 million loss splits into 12 million under a 2019 property policy with an inherited exclusion and 6 million under a 2024 cyber policy whose exclusion is conditional on a competent authority. The reflex is to present the widest line first. Why is that backwards?
Because the stake is the 12 million from 2019, whose exclusion is the weakest: that is where the characterization of the proximate cause is decided
Two thirds of the loss rests on the contract where the insurer's defense is weakest, and that is where the effort belongs. The opposite reflex comes from a habit that is reasonable elsewhere, starting with the cover best fitted to the facts. Here it means working first on the line where the insurer has the better tool, and neglecting the one where it has the worse. The answer saying the 2019 policy does not cover cyber deserves careful dismissal: a 2019 policy that does not mention cyber does not exclude it either, and that is precisely the definition of silent cyber. Absence of mention is not an exclusion, it is an exposure the insurer neither priced nor reserved, and discovers at the claim.
Glossary entry · notpetya8. A clause makes the exclusion conditional on official recognition, without saying at what date that recognition must exist. A settlement is signed in July, absent any attribution. In November, two governments publicly attribute the attack. Where is the risk?
That November's attribution is raised against a July settlement, the clause having fixed no date at which the condition must be met
The flaw is not in what the clause requires but in what it omits: a moment. A condition without a date stays open indefinitely, and a fact arising after settlement can then be presented as meeting it. The answer treating the settlement as final is a lawyer's, and it has real force: a well-drafted settlement, where the insurer does not reserve its position, does extinguish the dispute. Which is exactly why this is settled in the drafting and not afterwards: what protects is not the nature of the settlement, it is having written into the clause the date at which the condition is assessed, and having known, in July, what the insurer was reserving. The cession to the reinsurer raises the same question one level up, and a divergent answer there leaves the cedant alone.
Glossary entry · attribution-etatique9. A property policy written in 2019, which does not mention cyber, carries an inherited war exclusion. A wiper destroys the insured's ERP. The insurer invokes the exclusion. Who must prove what?
The insurer: an exclusion is a defense, and the NotPetya litigation showed that war and hostilities sit poorly with malicious code
The burden follows the nature of the clause, and an exclusion is pleaded as a defense: whoever invokes it must establish it. Reversing that burden, as the answer placing it on the insured does, would turn every exclusion into a presumption, which no policy provides for. The answer holding that a public attribution settles the matter by itself is the most interesting to set aside, because it mixes two orders: a public attribution is a fact, sometimes a powerful one, but on a wording speaking of war and hostilities without mentioning cyber it satisfies no contractual condition, it merely feeds the insurer's argument. That is the whole difference from a modern clause making attribution a condition: there, attribution satisfies the clause; here, it only argues. The practical consequence is counterintuitive: the oldest policy, the one most silent on cyber, gives the insured the strongest position.
Glossary entry · war-exclusion10. In 2017, NotPetya was attributed to Russia's GRU by several Western governments. What, under the London market's cyber war clauses, makes it a cyber operation?
The use of a computer system by a state, on its instructions or under its control
A cyber operation, under LMA clauses 5564 to 5567, is the use of a computer system by a sovereign state, on its instructions or under its control, to disrupt, deny access to or degrade the functioning of a computer system, or to copy, delete, manipulate or destroy the information it holds. The definition is deliberately broad and covers destructive attack as much as espionage or sabotage. What triggers it is therefore attribution to a state, not the scale of the damage nor the technique used: that is what the other three answers miss, and it is also why the litigation following NotPetya turned on attribution rather than on quantum. Delivery through EternalBlue and automatic propagation describe the event well, but they are not what brings the clause into play.
Glossary entry · cyber-operation11. A four-line tower: three carry the same definition of attribution, the fourth a different one. What does the programme's capacity table show?
A complete tower: a capacity table adds up capacities, it does not read definitions
The tool used to check that a tower is complete is blind to the one thing that can make it incomplete. A table carries amounts, layers, carriers and rates, and it adds up: four lines covering the whole tower appear there as a covered tower, whatever their wordings. The consequence is that a tower whose lines do not define attribution alike is not a tower, it is stacked covers that will respond separately on the same facts, and the insured will only learn this at the claim. Believing the hole would show if the lines were properly ordered, or would appear as reduced capacity, expects from the tool work it does not do: comparing clauses is human work, and nobody enters it in the table.
Glossary entry · tour-assurance12. A French bank, whose processing is hosted by an Irish cloud provider, suffers disruption during a state cyber operation aimed at another country's financial infrastructure. Its systems sit in no impacted state. What are such assets called?
Bystanding cyber assets
A bystanding cyber asset is, in the terminology of LMA 5567, the system of an insured or its suppliers that sits outside any state impacted by a state cyber operation, yet suffers damage through propagation or network dependency. The question the notion raises is easy to state and heavy in consequence: does the exclusion attached to the impacted state follow the damage out to those peripheral assets? That is exactly what the bystanding write-back, carried by LMA 5567A, settles by keeping cover for them. The case here shows why the question is not theoretical: a company can have no activity at all in the targeted country and still take most of the loss, because its processing chain runs through infrastructure the attack reaches. The geography of the damage has stopped coinciding with the geography of the business.
Glossary entry · bystanding-cyber-asset13. An attack on a SCADA system destroys a pump, valued at 0.4 million, and halts the line for nineteen days, for 14 million of business interruption. The group presents the whole loss under its cyber policy, which excludes physical damage to property. Where is the error?
You route by consequence, not by cause: the write-back for consequential physical damage reopens the property policy on the pump, and the business interruption flowing from it follows that same policy
The two contracts were drafted to meet at exactly this point, and routing is by consequence. The write-back reopens the property policy on the damaged asset and on the business interruption flowing from it; the cyber policy, excluding physical damage, does not carry the 0.4 million and answers for the system's unavailability. The same 14 million is therefore claimable under two contracts, on two different theories, and the split turns on a question with nothing legal about it: would the plant have stayed down nineteen days from the SCADA outage alone, or was the pump's lead time the critical path? If the plant could have restarted in three days and the pump imposed sixteen, then three days are cyber and sixteen are property. The whole file rests on a manufacturing lead time, and no clause says so. Sharing pro rata to the amounts is the answer of someone looking for a rule where there is only a fact to establish.
Glossary entry · perte-exploitation14. A 168-hour aggregation window runs on the portfolio from the hour the cedant selects. Each policy carries a twelve-hour waiting period, counted from its own interruption. What synchronizes the two clocks?
Nothing: one is counted on the portfolio, the other on each insured, and the gap widens on the longest files
Nothing links them, and it is a design flaw neither clause flags, since each is coherent taken alone. The consequence is concrete and always falls on the same files: an insured whose interruption begins late in the window sees its waiting period run as the window closes, and the indemnifiable part of its loss can sit entirely outside the ceded event. The longest interruptions are the most exposed to that mismatch, which is to say the heaviest claims, the ones the treaty was bought for. The other three answers assume a bridging mechanism that would be reasonable and does not exist in common wordings: they describe the treaty you would want, not the one you signed.
Glossary entry · delai-carence15. Four hundred insureds depend on the same host: 250 policies carry a 24-hour waiting period, 150 a 12-hour one. A twenty-hour outage occurs, and it is indeed a security failure. What does the portfolio produce?
The 250 produce nothing, and the 150 see eight hours of interruption beyond their threshold
A waiting period is a threshold before it is a deductible: below it the cover does not open at all, so there is nothing to reduce pro rata. The 24-hour policies see nothing on a 20-hour outage, and the 12-hour policies open for the eight excess hours. Portfolio loss as a function of outage duration is therefore a staircase and not a slope: it jumps at 12 hours, jumps again at 24, and between the two steps it does not move. Both proportional answers are the error of someone who read the period as a monetary deductible, which it is not. The answer invoking an average waiting period is the costliest because it looks prudent: an average waiting period describes no policy in the book, and a model that uses one is wrong about all of them.
Glossary entry · franchise-temporelle16. A cloud aggregation study is built on the list of insureds depending on the same host. What does it lack in order to predict a loss?
The generation of wording: dependency says who is exposed, wording says who is covered, and only the crossing of the two produces an indemnity
Dependency on a provider is a fact about the world, wording is a fact about the book, and the second decides. An older generation of contingent business interruption opens the cover only on a security failure at the provider; a recent generation opens it on any unavailability. On an accidental outage the first produces nothing, however many insureds are exposed. A book carries several generations at once, because wordings drift at every renewal, while the model knows only one. And there remains what the crossing itself does not show: on the day of a large outage every exposed insured notifies, including those whose cover will never open. Handling those files is a real, immediate expense, covered by nobody, which an aggregation modelling only indemnities leaves entirely out of the calculation.
Glossary entry · carence-fournisseur17. What decides, in practice, the line of business under which an industrial cyber loss settles, and why can the question not be caught up later?
Proof of physical impairment, which restarting destroys: the allocation is decided in the incident response plan, not in the contract
The clause says what would be covered if you knew what happened; you still have to establish it, and a team restarting a line erases the physical state of the affected components within hours. That is why the split is decided in the incident response plan, before any contract: photograph, record, keep the removed parts, date everything. The answer pointing to notification order deserves better than dismissal, because it targets a real effect: presenting under the cyber policy first extinguishes nothing on the property side, but installs with the adjuster a causation narrative centered on unavailability, which then has to be undone. That order therefore weighs on the file without deciding it. And while the question is settled, both insurers cede into two portfolios with different aggregation clauses, so no reinsurer sees the whole event.
Glossary entry · scada18. An online retailer is made unreachable for hours during a sales period by a flood of requests from a network of compromised machines. No data is stolen. Which cover responds, and why?
Business interruption cover, the harm being to availability
A distributed denial of service overwhelms an online service with such a volume of requests that it stops answering legitimate users, and the word distributed reflects that the attack comes simultaneously from many machines compromised without their owners' knowledge, gathered into a botnet. Its distinctive feature is seeking neither to steal data nor to penetrate the system: there is no exfiltration, no encryption, no intrusion, which is why the answer denying any cover for want of an intrusion looks plausible to anyone equating a cyber loss with a compromise. The harm is purely to availability, which places it with business interruption: the loss is measured in margin not earned during the outage, not in data lost. The timing the attacker chooses is not incidental and shows up in the amount, since the same duration of downtime costs far more during a sales campaign than on an ordinary day.
Glossary entry · deni-de-service-distribue19. Two wordings of the same treaty: one anchors the event on the first constituting act, the other on the first manifestation of damage. On a ten-week dormant compromise, which one serves the cedant?
The one anchored on manifestation: anchoring on the cause starts the clock at the compromise and closes it before anything happens
Both wrong answers pointing to the cause share an intuition that is right elsewhere and wrong here: in insurance, reaching back to the origin often widens cover. An aggregation window does not work that way, because it is not an extent but a duration that runs. Its starting point does not determine how far back you reach, it determines when it expires. Anchoring on the cause therefore does the exact opposite of what intuition promises. As for aggregating the compromise and the encryption into one event, that assumes the window is long enough to span ten weeks: one hundred and sixty-eight hours is one. The equal duration of the two windows is true and inconsequential, since the starting point is what decides.
Glossary entry · accumulation-cumul20. A 30 million layer above 8, per event, with a single reinstatement. March: 45 million ceded. July: 35 million. November: 20 million. How much does the cedant retain in November?
17 million: 8 of priority, plus 9 unprotected, the layer having only 3 million of limit left and no reinstatement
You have to follow the layer, not the loss. In March it pays its 30 million and is exhausted: the cedant retains 8 of priority plus 7 above the top, that is 15. The single reinstatement applies. In July the reinstated layer pays 27 and only 3 million of limit remains, with no reinstatement. In November, on 20 million, it pays only that 3: retention of 8 plus 9, that is 17. So the cedant retains more on the year's lightest loss than on its heaviest, a result no programme table shows. Answering 8 assumes a layer still intact, which it has not been since March; answering 20 forgets the 3 million that remain and must be claimed; answering 15 reasons by analogy with March, which is exactly how a programme gets read line by line instead of walked through as trajectories.
Glossary entry · point-attachement21. A 20 million layer above a 12 million priority, per event, with a single reinstatement. A mass event totals 50 million of ceded claims, and the chronology allows it to be declared as one event or as two of 25 million. What does each option return?
One event returns 20 million, the layer hitting its limit; two return 13 each, that is 26, but the single reinstatement is consumed on the first
As one event, 50 less 12 is 38, but the layer only carries 20: the top 18 million stays retained. As two events of 25, each recovers 13, that is 26 in total. Splitting therefore returns 6 million more. The answer invoking the double priority is the competent professional's, and it sees a real fact: paying the priority twice does cost 12 million more. It simply draws the wrong conclusion, because hitting the limit costs 18 million, which is more. And the true price of splitting is in none of those figures: it is the single reinstatement, consumed in one go, leaving the whole year with no second protection. The optimization that gains six million on the first event can cost far more on the third.
Glossary entry · reconstitution-garantie22. A per-event excess of loss treaty provides 25 million above an 8 million priority, with a 72-hour aggregation window whose start time is the cedant's to choose. Four clusters of claims: Monday 08:00 for 4 million, Tuesday 20:00 for 9, Thursday 14:00 for 7, Friday 06:00 for 5. Where should the window start?
Tuesday 20:00: the window then covers Tuesday, Thursday and Friday, that is 21 million, and recovers 13 million
You have to do the arithmetic, and the arithmetic contradicts instinct. Opening Monday 08:00 closes the window Thursday 08:00: it takes Monday and Tuesday, 13 million, of which 5 are recovered; Thursday and Friday then form a second event of 12 million, of which 4 are recovered, so 9 million in all. Opening Tuesday 20:00 closes it Friday 20:00: the window takes Tuesday, Thursday and Friday, 21 million, of which 13 are recovered, and Monday's 4 million stays alone under its priority. Thirteen against nine, for a thirty-six hour shift and no new facts. Opening Thursday returns what opening Monday returns, the two remaining clusters grouping on their own side. The answer saying the start time changes nothing is the belief this question targets: an aggregation clause does not share out a total, it cuts up a chronology, and two cuts of the same total are not worth the same, because each event pays its own priority and hits its own limit.
Glossary entry · traite-excedent-sinistres23. At renewal, an underwriting committee concluded that 'the programme covers two large events'. The year brings three, of medium size, and ends badly. In what way was the committee's sentence true and yet beside the point?
It tested severity when the year asked a frequency question: the limit answers the size of an event, the reinstatement answers how many times
The sentence is accurate, which is what makes it hard to challenge in the room: it answers a severity question, posed on a two-large-event trajectory. The year asked the other question. On a peril whose frequency is rising, the number of reinstatements decides the year, because a layer exhausted early leaves full exposure through December 31, and cyber has no season to close the window. The answer pointing to the priority is right about one thing, the retention repeats at every event, but the priority is a known, budgeted amount, whereas exhausting the layer removes the protection itself. A programme is therefore not read line by line, it is walked through as trajectories, and stop-loss is the form that answers a frequency question where per-event excess answers severity.
Glossary entry · stop-loss24. A software vendor is compromised on January 10 and the compromise lies dormant. Encryption fires on March 20 and hits the portfolio for three days. The treaty anchors the event on 'the first constituting act' and carries a 168-hour window. What happens?
The window ran from January 10 to 17 and closed nine weeks before the first damage: nothing aggregates, and that sentence is negotiated at placement, never at the claim
No exclusion was invoked, no cover was refused, and yet the whole recovery is destroyed by a definition. That is what makes this flaw so hard to see: it looks like nothing anyone monitors. The answer restarting the window at manifestation describes the other possible wording, the one that should have been obtained, and confusing it with the one that was signed is the exact error this kind of file reveals at the worst moment. The asymmetry is cruel: anchoring on the cause looks more generous since you reach further back, whereas reaching further back only starts the clock earlier, therefore closes it earlier. The cedant discovers the sentence at the claim, when nothing about it can be changed.
Glossary entry · spof-accumulation-cyber25. The SolarWinds attack, revealed in late 2020, planted a backdoor in a legitimate update distributed to thousands of organisations. Why is that pattern an accumulation problem for an insurer?
Because one compromised point reaches every insured trusting the same supplier, at the same moment
A supply chain attack compromises not the final target but a trusted link upstream, a software publisher, a service provider or an embedded component, to reach all of its customers by cascade. Rather than forcing a thousand doors, the attacker forces one, belonging to a party whose products are widely distributed, and uses the trust relationship as the vehicle. For an insurer the consequence is not the severity of any single loss, it is simultaneity: a book whose insureds operate in different sectors and countries, and which therefore looks diversified, stops being so the moment they share a supplier. The apparent diversification is about what the insureds do, the real exposure is about what they depend on, and the two do not coincide. That is what makes this family of attacks hard to bound with ordinary accumulation controls, which reason by geographic zone or by line of business.
Glossary entry · attaque-chaine-approvisionnement26. On 19 July 2024, a faulty content file published by a security vendor made its kernel driver read invalid memory, producing an endless blue screen loop on every machine running it. Why is a kernel-mode security agent an accumulation risk?
Because one update reaches every endpoint running it at once, at maximum privilege
Kernel mode is an operating system's most privileged execution level: a driver running there reaches all physical memory and hardware directly, without restriction. That is what makes security agents effective, since they can intercept a malicious system call before it runs, detect a rootkit, and make themselves impossible for hostile software to shut down. The same privilege creates the risk: an error in that code does not degrade the system, it stops it. The accumulation comes from two properties together, and they must be held together to understand the 2024 loss. The first is privilege, which turns a software defect into a total machine failure. The second is distribution: a content file is pushed to millions of endpoints within minutes, without the validation stages of a software release. A book of insureds spread across different sectors and countries then shares a single possible failure, and the diversification believed to be in place covers only their activities, not their dependencies.
Glossary entry · bsod-kernel-mode27. In December 2021, a vulnerability scored 10 out of 10 on CVSS was disclosed in a logging library used everywhere. Insurers then made renewal conditional on proof of patching. What does such a vulnerability represent for a book of business?
A dated common exposure that every insured shares at the same moment
The CVE catalogue, maintained by MITRE, assigns each known vulnerability a unique identifier and a public description; CVSS gives it a criticality score from 0 to 10, computed from ease of exploitation and impact on confidentiality, integrity and availability. A maximum score on a widely deployed library produces a situation no individual rating describes: it is not a high risk at each insured taken separately, it is the same risk at all of them, arising on the same date, that of disclosure. The practical consequence is that the book stops being a sum of independent exposures during the window between disclosure and patch, and that window is the only parameter the insurer can act on. This explains the urgent alerts sent to insureds and the proof of patching required at renewal: it is not about discipline but about shortening a common exposure the insurer cannot otherwise diversify away.
Glossary entry · cve-cvss28. An insurer finds that millions of automated login attempts on its customer portal opened 340 accounts, some of which had their bank details changed. The success rate is below one percent. What does this attack rely on?
On password reuse, tested from earlier breaches
Credential stuffing exploits a behaviour rather than a flaw: most people reuse the same credentials across services. The attacker buys or collects from underground forums lists of username and password pairs from past breaches, then automates attempts against valuable targets, banks, online retailers, insurers. That distinction matters for characterising the loss: nothing was breached, no vulnerability was exploited, the system worked exactly as designed by accepting valid credentials. The very low success rate, often under one percent, is not good news: at a scale of a million attempts it yields thousands of accounts, and it makes the attack profitable without requiring any particular skill. The consequences follow the account rather than the system, changed bank details, diverted reimbursements, and the notification duty is assessed on the data thereby reached.
Glossary entry · credential-stuffing29. After the July 2024 incident, security vendors operating at kernel level are pushed toward eBPF architectures, and a reinsurer lowers its stress scenario for faulty updates. What justifies that revision?
eBPF programs are verified by the kernel before being allowed to run
The Extended Berkeley Packet Filter allows custom programs to run inside the kernel, on Linux first and recently on Windows, but in a constrained and verified environment. That verification is what changes the scenario, and it is the only point that matters to a reinsurer. A traditional kernel driver runs with full privileges: an error there halts the whole system, as the 2024 outage showed worldwide. An eBPF program is first submitted to the kernel, which refuses to load it unless it can guarantee the program terminates and stays inside its sandbox. The defect is then rejected rather than executed, and the outage becomes a non-installation. The insurance lesson is interesting because it is rare: the severity of an accumulation scenario can fall without any insured changing behaviour, simply because the underlying technical architecture has moved. It is a case where risk drops by construction rather than by prevention.
Glossary entry · ebpf30. A model estimates the probable aggregate loss from an outage at a payroll provider used by 1,200 insureds at 85 million euros, or 2.3 times available net capacity. What does that ratio measure?
That one single scenario exceeds what the insurer can absorb alone
Cyber risk quantification seeks to put a figure on the probable cost of an event for an organisation or a book, through formal probabilistic models, of which the FAIR framework is the most widespread, or through stochastic simulation producing loss distributions from threat scenarios. The ratio described here says nothing about price or frequency, which is what the distractors wrongly offer: it compares a scenario loss with a capacity. At 2.3 times net capacity, the conclusion is not that the policies are mispriced but that a single event would exceed what the insurer can carry, whatever premium it collects. The question therefore becomes one of capacity and transfer, not of pricing, and it is dealt with before any loss occurs. That is also the value of such a model: it makes visible a concentration the income statement does not show, since as long as the scenario does not happen the book looks healthy.
Glossary entry · quantification-risque-cyber31. On the day of discovery, the finance department notes that the response costs sub-limit is by far the lowest of the four covers, and decides to preserve it: the usual providers will be engaged on the company's own funds first, and claimed later. What is that reasoning worth?
It reverses the causal order: this is the only one of the four covers whose prompt use reduces the other three, and preserving it means letting the items it would have bounded grow
The four covers of a cyber policy are not four pockets of different sizes to be emptied in any order: three pay a loss already formed, and only one sends people to work while the loss is still forming. Its sub-limit is low, which is a reason to read it before the loss, never to save it during. The first two days decide the extent of encryption, the volume taken out and the length of interruption, that is, three items out of four, and an hour gained on intervention weighs more than the entire sub-limit. The answer about prior consent states a fact, most policies reimburse off-panel providers only after consent and that consent is not given retroactively, but it reads the cover as a reimbursement line when it is the conduct of the loss. The one invoking backups confuses rebuilding with knowing: an offline backup shortens the interruption and says nothing about what left, therefore nothing about the liability to come.
Glossary entry · police-stand-alone32. At 11 a.m. on the day of discovery, the head of information systems commissions an investigation report from a specialist firm, in the company's name. What is the heaviest consequence, and when could it still have been avoided?
The report becomes a company document, disclosable in later civil or administrative proceedings, and that was decided in the first two hours by placing counsel ahead of the investigator
This 11 a.m. decision belongs to two covers at once, and nobody sees it that way at the time: it commits response costs, and it decides what third-party liability will be worth for years. A report commissioned by the company is a company document, and it will state, with the technical precision that is its merit, everything that had not been done; commissioned by counsel to prepare the defense, it enjoys a protection that varies by jurisdiction but exists. The answer about the off-panel provider is true and expensive, and it remains recoverable: consent can still be sought for what follows. The report answer is not, and that is what separates them. The one about erased traces names a real risk, but it bears on the technical quality of a document that can be redone, not on its legal fate, which can no longer be changed.
Glossary entry · incident-response33. Revenue 73 million euros, gross margin 30 percent, that is 60,000 euros of margin per day. Complete stoppage on June 1 at 4 a.m., restart to 50 percent on June 8, return to expected level on June 30. The policy carries a 24 hour waiting period that is deducted, a monetary deductible of 100,000 euros, and an indemnity period running to the return to expected level. The insured claims seven days of stoppage. What is missing from that claim?
660,000 euros: a return to 50 percent is not a recovery but a half loss that keeps running until June 30, and the indemnity goes from 260,000 to 920,000 euros
Seven days of stoppage make 420,000 euros, less one day of waiting period and 100,000 of deductible, that is 260,000. The real loss is close to four times that: six indemnifiable days at 60,000 make 360,000, then twenty-two days at half activity make 22 times 30,000, that is 660,000, giving 1,020,000 before the deductible and 920,000 after. The answer stopping everything on June 8 applies the property rule, where rebuilding bounds the interruption; the cyber indemnity period runs to the return to expected level, and an IT restart almost always precedes a commercial recovery by several weeks. The answer refusing to stack the two retentions confuses two things that do not measure the same quantity: the waiting period removes hours, the deductible removes an amount, and they stack because they do not overlap. The one counting the twenty-two days at the expected level indemnifies activity instead of indemnifying a shortfall: the company produced half, and it is the other half that is claimed.
Glossary entry · perte-exploitation34. A third-party liability policy carries a 5 million euro limit, defense costs inside the limit, facing a class action, a regulatory proceeding and four corporate customers invoking their indemnity clauses. What exactly does that erosion change in the handling of the file?
It converts time into indemnity cost: every month of proceedings on three fronts reduces what will be left to indemnify, and the choice between settling and litigating arises early, for a financial reason before a legal one
Third-party liability is a long tail item grafted onto an instantaneous event: claims arrive over years, before different jurisdictions, and the defense runs on three fronts that do not end together. An eroding limit then turns time into money, and the choice stops being a question of legal strategy and becomes a question of the amount left. The answer seeing only an accounting entry misses that shift. The one hoping for costs beyond the limit borrows from a wording where defense costs are in addition, which does exist and is precisely the line to read at placement: two otherwise identical policies are not worth the same on that single word. The one prioritizing the regulatory front confuses two separately true things, assistance costs in a proceeding are covered by most policies, and nothing makes them non-eroding. What makes it worse sits elsewhere and is not visible in the clause: for many service companies the heaviest exposure is the indemnity clauses signed toward a few dozen corporate customers, and that is exactly what the erosion reduces.
Glossary entry · alae35. The attackers announce they hold 400 gigabytes of data and demand a ransom. Management wants to pay at once to prevent publication. What must be said before the amount is even discussed?
That the stated motive is the one thing that does not hold: the data is already out and payment buys only an unverifiable promise, whereas what it really buys is time on the interruption, subject to two prerequisites, the insurer's consent and screening of the recipient against sanctions regimes
An insured paying to prevent a leak buys something that does not exist: the data left before the encryption, and no mechanism obliges an attacker to destroy it. One paying to shorten an interruption buys something real and imperfect, a slow key that fails on part of the files, and that amount compares coldly against the cost of a full rebuild. The answer keeping only one condition forgets one, and it is the harder of the two: a payment to a designated entity is prohibited whatever the cover. The one deferring screening until after transfer reverses who carries the prohibition, which bears on the payment itself and not on its reimbursement, reproducing here the shape seen elsewhere in this certification, a cover that responds to an expense one has no right to execute. The one excluding any ransom after exfiltration invents a restriction: the cover does not vanish, it is the motive for paying that changes nature. A useful and rarely stated fact goes with it: running the restoration in parallel lowers the value of what is being negotiated every day.
Glossary entry · ofac-sanctions-cyber36. Friday 5 p.m., traces of unauthorized access are found in a database of patient records for residents of three countries. Log analysis will take three to four weeks. The general counsel proposes waiting for the findings so as not to notify false information. What is to be decided?
The clock is already running, awareness requiring neither certainty nor understanding: notify within the deadline what is known, name what is unknown, announce the timetable, and informing the individuals concerned remains a separate obligation, on a different threshold and a different schedule
The general counsel's motive is honorable and that is what makes it dangerous: an authority discovering an unnotified breach handles two failures instead of one, and the second is the easier to establish. Phased notification exists precisely for the asymmetry between a short clock and slow knowledge, and it avoids the two symmetrical errors urgency produces, waiting for certainty and missing the deadline, or notifying broadly on the worst perimeter and exposing people who were not affected. The answer joining the two obligations confuses two that share neither threshold, informing individuals requiring a high risk, nor schedule, and that confusion leads to writing to patients on a perimeter not yet known. The one starting the clock at the end of the investigation reads awareness as certainty. Two things attach to this and are handled the same evening: the cost of informing individuals, addresses to find and a call center to open, falls under response costs, that is, the cover paying for the unfinished investigation; and three countries open parallel obligations whose contents cannot contradict each other.
Glossary entry · notification-violation-donnees37. On the questionnaire, to the question "are backups kept offline?", the group answers yes: a copy runs continuously to a separate account, with the cloud provider that already hosts production. Ransomware destroys production and the backup account. Where exactly is the defect?
Offline does not describe a separate account but a closed path, and a copy the same provider can reach closes nothing: the translation into a named perimeter, which account, which disconnection, which restore test, was due on the questionnaire
Nobody lied, and that is the ordinary shape of these files: one word taken for another rather than a false statement. A backup is not classified by its existence but by what it closes, and what it closes here is the path by which an attacker destroys the ability to rebuild; a copy reachable by the same provider, under the same administrative access, leaves that path open. It is also the single measure that decides between three days and six weeks of interruption, hence a severity measure and not a frequency one. The answer keeping only the proportional reduction knows the right regime and skips the question that comes before it: did the contract take this answer up as a mere declaration, describing a state on the day of placement, or as a condition, imposing a state throughout? The answer asserting it is always taken up as a condition turns into a general rule what has to be looked for contract by contract. And the one separating existence from location is exactly the error that ranking controls by what they close is meant to avoid.
Glossary entry · declaration-de-risque38. An actuary presents a five year series showing average cyber claim cost up 140 percent, and concludes the risk has worsened by as much. What adjustment does the series need before it can be read?
It mixes cover perimeters: the extension to business interruption without physical damage made the average cost jump with no change in any attack, and an unadjusted series measures the evolution of contracts as much as that of attacks
A cyber loss series measures two things at once and separates neither: what attackers do, and what contracts began to cover. The day policies covered business interruption without physical damage, the average cost jumped with no change in the number of attacks, and reading a trend off that amounts to pricing a drafting reform. The answer invoking inflation and exposure has the right instinct and the wrong measure: cyber cost is produced by daily revenue interrupted and by the number of records held, not by annual revenue, and that adjustment would leave the change of perimeter untouched. The answer discarding mass events is the most tempting for someone coming from another line, where removing a catastrophe to read an attritional trend is good practice: in cyber, correlation is not a contaminant of the series, it is a property of the risk, and removing it amounts to measuring the risk one would have preferred to carry. What replaces the history is not a better series anyway but a bundle: exposure, what the controls close, sector, and costed scenarios.
Glossary entry · tarification-exposition